CVE-2025-41244

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vmware:aria_operations:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:cloud_foundation_operations:9.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:open_vm_tools:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:open_vm_tools:13.0.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:telco_cloud_infrastructure:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:telco_cloud_platform:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:a:vmware:tools:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:tools:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

History

06 Nov 2025, 13:58

Type Values Removed Values Added
CPE cpe:2.3:a:vmware:telco_cloud_infrastructure:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:telco_cloud_platform:*:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:aria_operations:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:a:vmware:tools:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:cloud_foundation_operations:9.0:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:vmware:open_vm_tools:13.0.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:open_vm_tools:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*
First Time Microsoft
Vmware tools
Vmware
Linux linux Kernel
Debian
Microsoft windows
Linux
Vmware cloud Foundation Operations
Vmware aria Operations
Vmware cloud Foundation
Vmware telco Cloud Platform
Debian debian Linux
Vmware telco Cloud Infrastructure
Vmware open Vm Tools
References
  • () http://www.openwall.com/lists/oss-security/2025/09/29/10 - Mailing List, Third Party Advisory
  • () https://lists.debian.org/debian-lts-announce/2025/10/msg00000.html - Mailing List, Third Party Advisory
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-41244 - US Government Resource
References () http://support.broadcom.com/group/ecx/support-content-view/-/support-content/Security%20Advisories/VMSA-2025-0015--VMware-Aria-Operations-and-VMware-Tools-updates-address-multiple-vulnerabilities--CVE-2025-41244-CVE-2025-41245--CVE-2025-41246-/36149 - () http://support.broadcom.com/group/ecx/support-content-view/-/support-content/Security%20Advisories/VMSA-2025-0015--VMware-Aria-Operations-and-VMware-Tools-updates-address-multiple-vulnerabilities--CVE-2025-41244-CVE-2025-41245--CVE-2025-41246-/36149 - Permissions Required
References () https://blog.nviso.eu/2025/09/29/you-name-it-vmware-elevates-it-cve-2025-41244/ - () https://blog.nviso.eu/2025/09/29/you-name-it-vmware-elevates-it-cve-2025-41244/ - Exploit, Third Party Advisory
References () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36149 - () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36149 - Vendor Advisory

Information

Published : 2025-09-29 17:15

Updated : 2025-11-06 13:58


NVD link : CVE-2025-41244

Mitre link : CVE-2025-41244

CVE.ORG link : CVE-2025-41244


JSON object : View

Products Affected

vmware

  • open_vm_tools
  • aria_operations
  • cloud_foundation_operations
  • telco_cloud_platform
  • telco_cloud_infrastructure
  • tools
  • cloud_foundation

debian

  • debian_linux

microsoft

  • windows

linux

  • linux_kernel
CWE
CWE-267

Privilege Defined With Unsafe Actions